Identity in vsms — machine callers over private_key_jwt against an embedded OIDC provider with no shared secret anywhere, human login by authorization_code plus PKCE with Argon2id passwords, the two RBAC layers and their two vocabularies, and the synthetic system principal that must never be reachable from HTTP. Load when touching sms-auth, GatewayAuth, an @@allow clause's role logic, provisioning, or anything that decides who may do what.